{"id":"7df1713a-1a5b-4a4b-a071-dc83b144a101","title":"Esentutl Gather Credentials","description":"Conti recommendation to its affiliates to use esentutl to access NTDS dumped file. Trickbot also uses this utilities to get MSEdge info via its module pwgrab.","author":"sam0x90","status":"test","level":"medium","date":"2021-08-06","modified":"2022-10-09","tags":["attack.credential-access","attack.t1003","attack.t1003.003","attack.s0404"],"technique_ids":["T1003","T1003.003"],"logsource":{"category":"process_creation","product":"windows"},"falsepositives":["To be determined"],"references":["https://twitter.com/vxunderground/status/1423336151860002816","https://thedfirreport.com/2021/08/01/bazarcall-to-conti-ransomware-via-trickbot-and-cobalt-strike/"],"source_path":"rules/windows/process_creation/proc_creation_win_esentutl_params.yml","source_sha256":"91b63dcc1c4b5b915324e472b3583c62d21072c95b174da46c86baf90ba748b6","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_esentutl_params.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Esentutl Gather Credentials\nid: 7df1713a-1a5b-4a4b-a071-dc83b144a101\nstatus: test\ndescription: Conti recommendation to its affiliates to use esentutl to access NTDS dumped file. Trickbot also uses this utilities to get MSEdge info via its module pwgrab.\nreferences:\n    - https://twitter.com/vxunderground/status/1423336151860002816\n    - https://thedfirreport.com/2021/08/01/bazarcall-to-conti-ransomware-via-trickbot-and-cobalt-strike/\nauthor: sam0x90\ndate: 2021-08-06\nmodified: 2022-10-09\ntags:\n    - attack.credential-access\n    - attack.t1003\n    - attack.t1003.003\n    - attack.s0404\nlogsource:\n    category: process_creation\n    product: windows\ndetection:\n    selection:\n        CommandLine|contains|all:\n            - 'esentutl'\n            - ' /p'\n    condition: selection\nfalsepositives:\n    - To be determined\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1003","id":"T1003","name":"OS Credential Dumping","page":"techniques/enterprise/T1003/"},{"key":"enterprise/T1003.003","id":"T1003.003","name":"NTDS","page":"techniques/enterprise/T1003.003/"}],"data_path":"data/detection-rules/7df1713a-1a5b-4a4b-a071-dc83b144a101.json","kind":"sigma"}
